Skip to content

fix(deps): refresh lockfile to clear 4 transitive advisories - #117

Merged
Kamidzu9 merged 1 commit into
mainfrom
fix/dependency-baseline
Sep 30, 2026
Merged

Kamidzu9 merged 1 commit into
mainfrom
fix/dependency-baseline

Conversation

@Kamidzu9

Copy link
Copy Markdown
Member

Part of a dependency baseline sweep across the mivabyte org.

Audit: 4 -> 0 (3 high, 1 low)

package.json is unchanged in this PR. All four advisories were stale
lockfile entries whose parents already declared patched ranges — a plain
lockfile refresh was sufficient. package-lock.json is the only modified file.

Verification (Node 24.21.0, wiped node_modules)

Full gate, every step exit 0:

npm install          0
npm run typecheck    0
npm run build        0
npm run lint         0
npm run test:runtime 0   12 files / 89 tests
npm run test:coverage 0  100% statements / 96.37% branches
npm run format:check 0
npm run audit:source 0
npm run registry:check 0
npm run storybook:check 0
npm run bundle:check 0
npm run test:contracts 0  29 tests
npm run pack:check   0
npm run package:lint 0
npm run api:check    0

Coverage thresholds were not changed — nothing was weakened to get green.

Not run: test:e2e, test:design, storybook:build,
storybook:typecheck — these need a browser or a running Storybook server.

Left alone

All remaining outdated packages are majors: vitest 5.0.2,
@vitest/coverage-v8 5.0.2, typescript 7.0.2, recharts 3.10.1, zod 4.6.5,
@changesets/cli 3.0.3.

Why this repo got the most conservative treatment

ui is the shared @mivabyte/ui design-system package. ui-showcase consumes
it via github:mivabyte/ui#main, so a broken ui breaks every downstream
consumer. Hence: no manifest edits, no version bumps, lockfile only, and the
full gate run rather than just build.

All four findings were transitive, with zero direct dependencies
implicated, so no package.json range needed to change. Each was a stale
lockfile entry rather than a genuinely new vulnerability:

- brace-expansion 1.1.18 / 5.0.9 (high) via minimatch under
  eslint-plugin-jsx-a11y, @microsoft/api-extractor and
  eslint-plugin-import-x. Covers the DoS advisories: exponential
  expansion of non-expanding {} groups, unbounded expansion length,
  quadratic-time `{a},b}` rewrite and uncontrolled recursion on nested
  brace groups. Now 5.0.12.
- fast-uri 3.1.6 (high) via ajv 8.20.0 under @hookform/resolvers and
  @microsoft/tsdoc-config. ajv already declares ^3.0.1, which admits the
  patched 3.1.8; the lockfile had not moved. Covers the authority
  injection and unclosed-bracket host confusion.
- js-yaml 4.3.1 / 3.15.1 (high) via @changesets/cli, @changesets/parse
  and read-yaml-file. Now 4.3.2 / 3.15.2, which is where the CVE-2026-59870
  !!omap quadratic-CPU fix and the maxTotalMergeKeys fix actually land.
- esbuild 0.27.7 (low) via tsup. Now 0.28.1, clearing the 0.27.3 - 0.28.0
  Windows dev-server arbitrary file read.

A non-force `npm audit fix` moved all four inside ranges their parents
already declared, and left package.json byte-identical.

npm audit: 4 -> 0 (3 high, 1 low -> 0).

Verified, all exit 0: npm install, typecheck, build, lint, test:runtime
(12 files / 89 tests), test:coverage (100% stmts, 96.37% branches,
unchanged thresholds), format:check, audit:source, registry:check,
storybook:check, bundle:check, test:contracts (29 tests), pack:check,
package:lint, api:check.

No engines inconsistency: package.json is untouched, so the engines
">=20" pin and the Node 22/24 CI matrix are unaffected.

Not run, needs a browser or a Storybook server: test:e2e, test:design,
storybook:build, storybook:typecheck.

Reported, not taken - all majors: vitest 5.0.2 and @vitest/coverage-v8
5.0.2 (repo is on 4.1.11, already outside the vulnerable 2.1.0-beta.1 -
4.1.10 range), typescript 7.0.2, recharts 3.10.1 (the 2.x branch is
deprecated but not vulnerable), zod 4.6.5, @changesets/cli 3.0.3.
@Kamidzu9
Kamidzu9 merged commit 5f87715 into main Sep 30, 2026
13 checks passed
@Kamidzu9
Kamidzu9 deleted the fix/dependency-baseline branch September 30, 2026 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant